ZeroHour

CVE-2021-24800

PoC
CVSS 3.1
4.3 medium
EPSS
<1%p49
Published
()
Modified
Description

The DW Question & Answer Pro WordPress plugin through 1.3.4 does not check that the comment to edit belongs to the user making the request, allowing any user to edit other comments.

Vendors
designwall
Products
dw question \& answer
Ecosystems
WordPress
Weakness
CWE-639
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.